Not ready to publish. Company registration details, the physical address and the Information Officer are still unfilled. ECTA § 43(1) requires them, and a policy that names no responsible party is unenforceable and misleading. Fill in src/lib/legal/entity.ts before launch.

Draft pending legal review. These documents were drafted against POPIA, ECTA, the CPA and PAIA, but not by an admitted attorney. Enc0ded processes identity documents and special personal information, where the consequences of a defective notice fall on the data subject. Have them reviewed before they are relied on.

Privacy policy

Version 1.0 · Last updated 22 August 2026

This policy explains what personal information Enc0ded collects, why, who it is shared with, how long it is kept, and what you can require us to do about it. It is written to satisfy the notification duty in section 18 of the Protection of Personal Information Act 4 of 2013 (POPIA).

1 Who is responsible for your information

The responsible party, as POPIA uses that term, is:

Legal name
[TO BE COMPLETED BEFORE LAUNCH]
Trading as
Enc0ded
Registration number
[TO BE COMPLETED BEFORE LAUNCH]
Physical address
[TO BE COMPLETED BEFORE LAUNCH]
Information Officer
[TO BE COMPLETED BEFORE LAUNCH]
Information Officer contact
[TO BE COMPLETED BEFORE LAUNCH]

The Information Officer is registered with the Information Regulator and is accountable for compliance with POPIA. Address any question, request or complaint about your information to them first.

2 What we collect, and why

Enc0ded exists to reduce how much of your identity you have to hand over. It therefore holds less than most services, and holds the most sensitive material in a form we cannot read.

InformationWhy we process itLawful basis
Email address, nameTo create and secure your account, and to contact you about itPerformance of the contract (POPIA § 11(1)(b))
Identity documents you upload (ID, passport, proof of address, payslips)To store them for you and release them only to recipients you nominateYour consent (§ 11(1)(a)), which you may withdraw
Security score answersTo calculate and show your exposure scoreConsent (§ 11(1)(a))
Email addresses you ask us to monitorTo check them against known breach dataConsent (§ 11(1)(a))
Digital Legacy credentialsStored as ciphertext only; we cannot decrypt themConsent (§ 11(1)(a))
Payment recordsTo take payment and to meet tax record-keeping obligationsContract, and legal obligation (§ 11(1)(c))
Audit log: sign-ins, document access, share-link use, IP addressTo detect and evidence unauthorised access to your accountLegal obligation to secure information (§ 19), and our legitimate interest (§ 11(1)(f))

A South African identity number, and the documents that carry it, count as personal information requiring particular care. Where a document you upload contains information about your health, biometrics or similar, POPIA § 26 treats it as special personal information and it is processed only on the strength of your consent under § 27(1)(a).

3 What we cannot read

Digital Legacy credentials are encrypted in your browser under a master password that is never transmitted to us. We hold ciphertext, a salt and a wrapped key. We cannot decrypt them, we cannot reset that password, and we cannot produce those credentials in response to a subpoena — not as a matter of policy, but because we do not have the means.

The same applies to anything wrapped to a Digital Legacy nominee's key. Only their passphrase opens it.

Documents in your vault are a different case, and we state the difference plainly rather than let the sentence above cover both. Those are encrypted at rest by our storage provider, which means the provider holds the key. Access is controlled by database policy so that only you and recipients you nominate can retrieve them — but it is access control, not mathematics, and you should judge it as such.

4 Who your information is shared with

We do not sell personal information, and we do not share it for anyone else's marketing. It reaches third parties only in these cases:

RecipientWhat they receiveWhere
Supabase (database, storage, authentication)All account data and uploaded documentsRegion as configured for the project
Vercel (application hosting)Request metadata and application logsGlobal edge network
Resend (transactional email)Recipient address and message contentUnited States
PayFast (payment processing)Amount, reference and your email address. Card details go to them directly and never reach usSouth Africa
Have I Been Pwned (breach monitoring)The addresses you ask us to monitorAustralia / global
Recipients of a share link you createThe specific document you chose, for the period you setWherever they are

Each of these is an operator under POPIA § 21 and processes your information only on our instructions, under a written agreement requiring them to secure it.

Several operate outside South Africa. POPIA § 72 permits that where the recipient is subject to a law or binding agreement providing comparable protection; the transfers above rest on contractual terms to that effect. If you want the specifics for a particular provider, ask the Information Officer.

We will disclose information where a law compels us to. Where we are permitted to tell you that it happened, we will.

5 How long it is kept

InformationRetentionWhy
Vault documents, credentials, share links, scores, alertsUntil you delete them, or 30 days after your account is deletedNo reason to keep them longer
Payment recordsFive years, with your identity detached from themTax Administration Act § 29
Audit logFive years, with your name removed on deletionEvidence of unauthorised access; POPIA § 19
Consent recordsFor as long as we rely on the consent, plus three yearsPOPIA § 11(2)(b) puts the burden of proving consent on us

When you delete your account we destroy everything except the two categories above, and those are stripped of anything identifying you. This is set out in full on your data page.

6 Your rights

Under POPIA you may, at any time:

  • Ask what we hold about you (§ 23). Download it yourself from your data page, or ask the Information Officer. We respond within 30 days.
  • Correct or delete it (§ 24). You can edit most of it directly, and delete your entire account from the same page.
  • Object to processing (§ 11(3)) on reasonable grounds, where we rely on legitimate interest.
  • Withdraw consent (§ 11(2)(b)). Where consent was the basis, withdrawing it stops that processing. It does not undo what was lawful before you withdrew.
  • Refuse direct marketing (§ 69). We do not send marketing by default.
  • Complain to us, and to the Regulator (§ 74).

Exercising any of these is free and will not degrade your service.

7 Security

POPIA § 19 requires us to secure the integrity and confidentiality of your information with appropriate, reasonable technical and organisational measures. What we actually do:

  • Access is enforced in the database itself, by row-level policies, so a fault in the application cannot expose another customer's records.
  • Documents are stored in a private bucket, retrievable only through short-lived signed links issued after a policy check.
  • Share links expire, limit the number of views, and require a one-time code sent to the recipient's address.
  • Digital Legacy credentials are encrypted in your browser before transmission.
  • Every access is written to an append-only audit log which no customer, and no member of staff, can alter or delete.

No system is beyond compromise. If your information is accessed unlawfully, POPIA § 22 requires us to notify the Regulator and you as soon as reasonably possible, and we will tell you what was affected and what to do about it.

8 Children

Enc0ded is for adults. We do not knowingly collect the personal information of a child under 18, and family plan members confirm they are adults when they accept an invitation. POPIA § 34 prohibits processing a child's information without a competent person's consent, and we are not set up to obtain or verify it.

If you believe a child has an account, tell the Information Officer and we will delete it.

9 Automated decisions

Your security score is calculated automatically from answers you give. It is informational: nothing is refused, priced differently or restricted on the basis of it, so POPIA § 71 — which concerns decisions with legal or substantial consequences made purely automatically — does not apply. The score's weightings are indicative rather than actuarially validated, and the score page says so.

10 Complaints

Please raise a complaint with our Information Officer first, at [TO BE COMPLETED]. If you are not satisfied, you may complain to the Regulator:

Authority
Information Regulator (South Africa)
Address
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Complaints
complaints.IR@justice.gov.za
Website
https://inforegulator.org.za

11 Changes

If we change this policy in a way that affects how your information is used, we will tell you before it takes effect and, where the change rests on consent, ask for it again. Every version is recorded against the consent you gave, so it is always possible to establish which text you agreed to.